Class A
- Must Class A providers include automated validations in the SDR?
- Can we include historical KSI metrics in Class A?
- Do we need to address every Class A KSI?
- What automation is recommended for Class A vulnerability monitoring?
- Is “see the SOC 2 report” an acceptable response to FedRAMP rule?
- Which external frameworks are accepted for Class A?
- What must be in a Class A Certification Package?